Principal Cybersecurity Architect AI

Florida BlueUnited StatesHybridFull-timeJunior, 1–2 yearsListed 1 hour ago

Apply now

About this role

The Principal Cybersecurity Architect – AI & Agentic Systems is responsible for driving enterprise-wide technology security strategy and providing technical expertise to business areas and project teams, with an emphasis on the implementation of innovative, leading-edge security technology solutions. The role carries specific accountability for the secure adoption of artificial intelligence at the enterprise: generative and predictive AI, retrieval-augmented systems, autonomous and semi-autonomous agents, and the Model Context Protocol (MCP) servers, tools, and connectors through which agents reach enterprise systems and Protected Health Information. The Principal Cybersecurity Architect – AI & Agentic Systems performs thorough enterprise-wide analysis ensuring the highest levels of confidentiality, integrity, and availability, and provides leadership and consultative guidance on projects with extensive size, scope, and risk. The role is responsible for coaching and providing technical oversight to others. It serves the company as an advisor on best practices and as an information technology strategy driver, implementing the principles, models, designs, standards, and guidelines that ensure enterprise technology is consistent, usable, secure, and adds value to the business. Because the company operates as a HIPAA covered entity and business associate, this role is accountable for ensuring that every AI system and agent touching electronic Protected Health Information satisfies the same Privacy Rule, Security Rule, and Breach Notification Rule obligations that apply to a human workforce member performing the same function — minimum necessary access enforced technically rather than by instruction, operation-level audit controls, encryption, executed Business Associate Agreements, and demonstrable risk analysis. The role is expected to make AI adoption faster and safer at the same time: the measure of success is the volume of AI capability the business is able to place into production on approved patterns, not the number of use cases blocked.

What You Will Be Doing

- Leading project management through the steps of the venture design process. Successfully deliver projects on time and on budget.
- Drive cross functional collaboration with key stakeholders across the organization (e.g. legal, medical, procurement, business units, project/program managers of connected efforts) at the appropriate times to drive projects through the steps of the venture design process
- Customer and expert recruitment/scheduling and interfacing with vendors for research and co-creation activities.
- Ensure all Stage-Gate preparations are complete. Manage Gate submissions for executive and steering committee review.
- Knowledge management: organize, document, and create best practices from collected project knowledge to create best practices for the innovation team.
- Designs the technical controls that keep Protected Health Information (PHI) inside HIPAA boundaries when AI and agents are in the data path: field-level PHI classification ahead of agent access, minimum necessary enforcement at a centralized context-delivery layer, chunk-level access control in RAG retrieval, de-identification and tokenization, prompt and output redaction at the point of input, prevention of PHI persistence in model weights, embeddings, caches, memory stores, prompt logs, and observability tooling, and tenant and workload isolation.
- Designs runtime protection for AI and agentic workloads, including AI and MCP gateway mediation of all model and tool traffic, input and output guardrails, prompt-injection and jailbreak defenses, tool-call authorization and rate limiting, sandboxed and isolated code execution, egress filtering to break the data-exfiltration path, context and memory scoping, and behavioral anomaly detection tuned to agent action patterns rather than traditional user baselines.
- Establishes AI and agent observability and auditability sufficient to satisfy the HIPAA Security Rule audit controls standard (45 CFR §164.312(b)) at the operation level: tamper-evident, immutable logging of which agent accessed which PHI, what action it took, under what authorization, and on whose behalf, plus retained decision traces linking every AI-influenced output to its source data, policies, and logic.
- Establishes and maintains the enterprise AI asset inventory and AI Bill of Materials (AIBOM) covering models, agents, prompts, datasets, embeddings, MCP servers, tools, and AI-enabled vendor features. Partners with Security Operations to detect and govern shadow AI and unapproved AI usage across the enterprise and the software development lifecycle.
- Leads governance processes for intake, review, and lifecycle management of new AI and non-AI technologies and solutions. Serves as the senior security voice on the enterprise AI governance body, setting risk-tiering criteria, pre-deployment assessment requirements, conditions of approval, monitoring obligations, and decommissioning standards.
- Embeds security into the AI and agentic development lifecycle (MLSecOps / AI SDLC). Partners with data science, MLOps, platform, and DevOps teams to shift controls left into CI/CD — model and dependency scanning, secrets detection, prompt and configuration review, evaluation gates, policy-as-code enforcement, and continuous posture assessment and remediation workflows.
- Owns the security architecture requirements for AI-related third-party and supply-chain risk. Defines pre-contract security requirements for AI vendors and models, ensures Business Associate Agreements and security addenda are in place before PHI reaches any AI service, evaluates AI frameworks, agents, vector databases, and AI platforms for enterprise readiness, and influences vendor roadmaps and future product releases.
- Ensures AI and agentic architectures are demonstrably aligned to applicable regulation and recognized frameworks, including the HIPAA Privacy, Security, and Breach Notification Rules and anticipated Security Rule amendments, HITECH, the NIST AI Risk Management Framework and generative AI profile, NIST Cybersecurity Framework, HITRUST, SOC 2, state AI and health-data statutes, and CMS and payer program requirements. Produces the architecture evidence auditors and regulators request.
- Serves as security architecture subject matter expert to business areas, project teams, client groups, and vendors — with emphasis on AI-enabled workflows such as utilization and prior authorization, claims and payment integrity, care management, member and provider service, appeals and grievances, coding, and enterprise productivity copilots. Leads efforts to examine technology vision, opportunities, and challenges.
- Builds consensus around the principles of security architecture, including the principles of least privilege and least agency for autonomous systems, and interprets and clarifies these principles for technical and business audiences.
- Participates in the evaluation, selection, and implementation of technology solutions, including AI security tooling such as AI and MCP gateways, AI security posture management, data security posture management, model and agent scanning, guardrail engines, and AI red-team platforms. Provides detailed pros-and-cons and build-versus-buy analysis and total cost of ownership assessment.
- Maintains operational, architectural, and design documentation including procedures, task lists, architecture blueprints, agent and data-flow diagrams, control mappings, and reusable design components and patterns that can be reused between projects.
- Establishes and leads an AI red-teaming and adversarial evaluation program. Defines the enterprise methodology for AI security assessment across applications, agents, tools, and multi-step workflows; commissions and oversees internal and third-party engagements explicitly covering agentic and MCP attack patterns, not solely model-level testing; and drives remediation of findings to closure.
- Investigates and reports on security threats and incidents involving AI and agentic systems. Develops and maintains AI-specific incident response playbooks addressing prompt-injection compromise, agent credential abuse, rogue and drifted agent behavior, poisoned memory or tooling, and PHI exposure through prompts, logs, or non-BAA services, including breach-assessment triggers. Conducts post-event reviews and drives corrective action. (5%)
- Provides technical leadership, coaching, and oversight to less experienced Cybersecurity Architects and to engineering and data science partners, promoting knowledge-sharing and professional growth. Continually enhances own breadth and depth of knowledge, benchmarks technology strategies and architectures against peer payers and industry, monitors and anticipates trends, and prepares benchmarking reports and presentations for leadership.

What We Require

- 8+ years related work experience as an Architect working on progressively complex IT and cybersecurity projects, including enterprise-wide initiatives with significant size, scope, and risk. Including at least
- 1 year hands-on experience designing, securing, assessing, or governing production AI/ML, generative AI, or agentic systems, including at least one implementation in which the candidate personally defined controls for model or agent access to sensitive regulated data.
- Related Bachelor’s degree or additional related equivalent work experience IT related field. Computer science, cybersecurity, information systems, data science, or engineering preferred.
- Required CISSP - Certified Information Systems Security Professional
- Expert-level knowledge of Information Security procedures and controls, including defense in depth, trust levels, privileges, and permissions.
Expert proficiency in creating architectural designs for progressively complex environments, and demonstrated ability to translate security principles into enforceable technical controls rather than policy statements alone.
- Demonstrated working knowledge of modern AI architecture: large language models, prompt and context engineering, embeddings and vector stores, retrieval-augmented generation, fine-tuning and model customization, inference serving, orchestration frameworks, and single- and multi-agent designs.
- Working knowledge of the Model Context Protocol (MCP) — including its trust model, tool discovery and invocation flow, transport and authorization patterns, and the security implications of connecting an agent to multiple MCP servers.
- Demonstrated understanding of AI-specific attack techniques and mitigations: direct and indirect prompt injection, jailbreaks, tool and function abuse, excessive agency, insecure output handling, training-data and memory poisoning, model inversion and extraction, membership inference, embedding inversion, adversarial examples, and AI supply chain compromise.
- Expert-level knowledge of identity and access management as applied to non-human and machine identities, including workload identity, OAuth 2.0 and OIDC authorization flows, token scoping and lifetime management, secrets management, just-in-time and just-enough access, and privileged access management.
- Expert-level knowledge of the HIPAA Privacy, Security, and Breach Notification Rules and their application to automated and AI-driven access to PHI, including the minimum necessary standard, audit controls, encryption, risk analysis, and Business Associate obligations. Ability to articulate why a system prompt or model instruction is not an access control.
- Working knowledge of the NIST AI Risk Management Framework, NIST Cybersecurity Framework, ISO/IEC 42001, MITRE ATLAS, and the OWASP GenAI, agentic, and MCP security projects, and the ability to apply them as design and assessment tools rather than as reference reading.
- Extensive knowledge of data security and data governance practices — classification, lineage, de-identification, tokenization, encryption in transit and at rest, key management, data loss prevention, and data security posture management — and how each is affected when a non-deterministic system sits in the data path.
- Expert-level knowledge of application and API security, including authentication and authorization patterns, input validation, secure integration design, and API gateway controls.
- Extensive knowledge of secure software development practices and the ability to embed controls into CI/CD and MLOps pipelines. Ability to read code and infrastructure-as-code well enough to review an AI or agent implementation independently.
- Mastery of a variety of platforms including distributed platforms, mainframe, container and Kubernetes environments, desktops, and mobile devices, with experience and understanding of a variety of operating systems.
- Expert consulting, negotiating, communicating, consensus building, presentation, and facilitation skills, with the ability to communicate highly complex technical information clearly and articulately at all levels and audiences — including the ability to give a business owner a defensible, timely answer on an AI use case rather than a blanket refusal.
- Expert-level ability to understand overall IT strategy and apply and implement it in assigned projects and initiatives, including decision-making related to implementing architecture and design.
- Expert innovator with the ability to think beyond established standards and processes, and demonstrated ability to reason about controls for systems whose behavior is probabilistic and only partially specified.
- Demonstrated ability to learn from mistakes and apply constructive feedback to improve performance.
- Exceptional leadership skills demonstrated through project or technical leadership experience, and knowledge of project management methodologies.
- Expert-level knowledge of common information management systems.

What We Prefer

- Health plan, payer, or other health care industry experience, including familiarity with PHI-bearing workflows such as claims, enrollment, prior authorization and utilization management, care management, appeals and grievances, provider data, and member service. Hands-on experience with enterprise AI platforms and agent frameworks:

Microsoft Azure AI Foundry, Azure OpenAI, Azure API Management, Microsoft Copilot and Copilot Studio; AWS Bedrock; Google Vertex AI;
- Databricks (Unity Catalog, MLflow); and agent frameworks such as LangChain, LangGraph, AutoGen, CrewAI, or Google ADK.

- Hands-on experience deploying or evaluating AI gateways, MCP gateways or proxies, LLM firewalls and guardrail engines, AI security posture management (AI-SPM), and data security posture management (DSPM).
- Experience with AI red-teaming and evaluation tooling such as Microsoft PyRIT, Garak, or equivalent, and experience running or commissioning adversarial testing of agentic workflows.
- Identity and Access Management experience spanning workforce, consumer, and non-human/agent identity, including consumer identity security for member-facing digital experiences.
- Experience securing APIs at enterprise scale, including experience with health care interoperability standards and interfaces (FHIR, HL7, X12 EDI) and the specific risks of exposing them to AI agents.
- Working proficiency in Python and familiarity with common data science and AI libraries, sufficient to prototype controls and validate implementations.
- Experience with privacy-enhancing technologies including differential privacy, synthetic data generation, and confidential computing.
- Experience preparing AI systems for external assurance — HITRUST, SOC 2.
- Experience using Agile methodology, and experience operating inside a formal enterprise architecture review or governance board. 2 or more years cloud security experience

General Physical Demands

- This position offers a hybrid work arrangement which combines flexibility with in office engagement. Team schedules are determined based on role requirements and business needs. Travel to and from our corporate offices may be required.
- Sedentary work: Exerting up to 10 pounds of force occasionally to move objects.
- Jobs are sedentary if traversing activities are required only occasionally.

What We Offer
As a Florida Blue employee, you will be at the heart of GuideWell’s vision – to lead the nation in transforming health through compassionate, connected, and technology-enabled care that delivers personalized value and empowered living.

To support your wellbeing, comprehensive benefits are offered. As an employee, you will have access to:

- Medical, dental, vision, life and global travel health insurance
- Income protection benefits: life insurance, short- and long-term disability programs
- Leave programs to support personal circumstances
- Retirement Savings Plan including employer match
- Paid time off, volunteer time off, 10 holidays and 2 well-being days
- Additional voluntary benefits available; and a comprehensive wellness program

Employee benefits are designed to align with federal and state employment laws. Benefits may vary based on the state in which work is performed. Benefits for intern, part-time and seasonal employees may differ.

To support your financial wellbeing, we offer competitive pay as well as opportunities for incentive or commission compensation. We also conduct regular annual reviews with pay for performance considerations for base pay increases.

Typical Annualized Hiring Range: $153,800 - $192,200

Annualized Salary Range: $153,800 - $249,900

Final pay will be determined with consideration of market competitiveness, internal equity, and the job-related knowledge, skills, training, and experience you bring.

We are an Equal Employment Opportunity employer committed to cultivating a work experience where everyone feels like they belong and can perform at their best in pursuit of our mission. All qualified applicants will receive consideration for employment.